A single-node Kubernetes cluster without Pod Security admission, with a foothold that may only create workloads and exec into them in one namespace. Bishop Fox's Bad Pods manifests (privileged, hostPath, hostPID, hostNetwork, hostIPC and combinations) show eight ways to turn that into node and cluster compromise.
Not startedVMcommit 61c96bbx86_64Secret
From the player's namespace-bound access, get root on the node and read /root/flag.txt.
The brief for this lab lives in its repository.